PT-2017-6871 · WordPress · Image Export Plugin

Larry W. Cashdollar

+1

·

Published

2017-05-23

·

Updated

2017-06-08

·

CVE-2015-5609

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Image Export plugin version 1.1 for WordPress
Description The issue allows remote attackers to read and delete arbitrary files by providing a full pathname in the file parameter to the "download.php" endpoint.
Recommendations For Image Export plugin version 1.1, consider disabling the download.php functionality until a patch is available to prevent exploitation. Restrict access to the file parameter in the download.php endpoint to minimize the risk of arbitrary file reading and deletion.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-5609

Affected Products

Image Export Plugin